Nlnetlabs Unbound — CVE-2026-50252 (Critical)

Date Jul 22, 2026
Type Vendor advisory
Signal Critical vendor advisory
Vendor / Product Nlnetlabs · Unbound
CVE CVE-2026-50252
Critical vendor advisory CVE-2026-50252

Summary

In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this secrecy is undermined. The vulnerability arises when the load balancing policy is consistent with respect to the incoming source UDP port and IP address while heavily depending on the incoming source UDP port as a randomization source. When the SO_REUSEPORT configuration option is enabled ('so-reuseport: yes') in Unbound (

Why it matters

This CVE carries a CRITICAL severity rating (CVSS 9.3) in Nlnetlabs Unbound. Patch or mitigate promptly. EPSS percentile: 2%.

Operator check

Review CVE-2026-50252 in your asset inventory. Apply patches per vendor guidance and verify Unbound is not exposed. CVSS score: 9.3. EPSS probability: 0.1%; percentile: 2%.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.